Last updated: September 27, 2026
This page lists the outside companies that Tally Integrations LLC ("Tally", "we", "us") uses to process personal data on behalf of our customers when they use Tally Sign. It is the list of Subprocessors authorized under Section 8 of our Data Processing Addendum (the "DPA"), as updated under Section 5 below. Annex III of the DPA reproduces it as of the DPA's effective date. Capitalized words not defined here have the meaning in the DPA or our Terms of Service.
1. What a subprocessor is
1.1 When a company (our "Customer") uses Tally Sign, it decides what documents to send and who to send them to. For that data the Customer is the controller (or "business" under California law), and Tally is its processor (or "service provider").
1.2 A subprocessor is a third party that Tally engages to process Customer Personal Data (as defined in the DPA) so that we can provide the Service. That includes a provider one of our subprocessors uses to do its work for us, such as a model host that OpenRouter passes requests to. Examples of Customer Personal Data: names and email addresses of Recipients, what Signers type into fields, signatures, signed PDFs and audit trails (including Signers' IP addresses and browser details), and data synced from a connected Salesforce org.
1.3 Under the DPA, each subprocessor must be bound by a written agreement with data protection obligations at least as protective as those in the DPA, to the extent they apply to the service it provides. Where a subprocessor uses its own providers to do its work for us, it must pass those obligations on. We remain fully liable to our Customers for the work of our subprocessors, as the DPA describes.
2. Summary
| Subprocessor | Purpose | Customer Personal Data | Location | Contracting entity |
|---|---|---|---|---|
| Railway (railway.com) | Hosts the application, its database, its file storage and database backups; receives application logs. Always used. | All Customer Personal Data held in Tally Sign | United States. Application and database: US West (California). File storage: San Jose, California | Railway Corporation |
| Resend (resend.com) | Delivers every email Tally Sign sends. Always used. | Recipient and sender names and email addresses, email content, and attachments, including signed PDFs with their Certificate of Completion | United States | Plus Five Five, Inc. (trading as Resend) |
| OpenRouter (openrouter.ai) | Passes requests from the in-app AI assistant to a host that runs the AI model we've selected, and returns the reply. Used only when someone in the Customer's account uses the AI assistant. | The draft or template being edited (including signer details and fill-in values entered in it), the conversation with the assistant, and pictures the User attaches | United States | OpenRouter, Inc. |
| AI model hosts for Anthropic's Claude models | Run the AI model that writes the assistant's replies. Used only when someone in the Customer's account uses the AI assistant. | The same content as OpenRouter, as passed on by OpenRouter | United States | No direct contract with Tally: engaged through OpenRouter, Inc. (see Section 3.4) |
Tally Sign doesn't offer a choice of hosting region. Customer Personal Data is stored in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, see Section 6 on international transfers.
3. Subprocessors in detail
3.1 Railway (hosting, database, file storage)
- Contracting entity: Railway Corporation (United States)
- What it does: Runs the Tally Sign web application and API, the Postgres database, and a private file storage bucket. Railway also keeps the database backups and receives the application's server logs.
- Customer Personal Data involved: All Customer Personal Data held in Tally Sign. That includes documents, templates and versions, Recipients and their field values and signatures, audit trails with IP addresses and browser details, comments and suggested edits, signed PDFs, PDF exhibits, uploaded files and page images, company logos and images, and records of Salesforce activity. Server logs can contain email addresses and email subject lines.
- Where: United States. The application and database run in Railway's US West region (California). Files (signed PDFs, exhibits, uploads, page images and logos) are kept in a Railway storage bucket in San Jose, California, where they were moved on September 25, 2026. Before that, they were kept in the database in US West.
- Backups and logs: Railway keeps daily, weekly and monthly backups of the database for up to 3 months. Deleted files and data therefore remain in backups until those backups expire, up to 3 months. Server logs are kept for 30 days.
- Transfer safeguard: Tally receives Customer Personal Data in the United States under the SCCs and UK Addendum in the DPA. Railway processes it in the United States under a written agreement that binds it to the same data protection obligations, as Clause 8.8 of the SCCs requires.
3.2 Resend (email delivery)
- Contracting entity: Plus Five Five, Inc., which operates the Resend service (United States)
- What it does: Delivers all email that Tally Sign sends, from our sending domain mail.tallysign.com. That covers signing requests, reminders, void notices, completed-document emails, negotiation messages, automation emails the Customer sets up, and notices to the Customer's own Users (such as invitations, security alerts and billing notices).
- Customer Personal Data involved: Recipient email addresses, Recipient and sender names, subject lines, message text and HTML, reply-to addresses, and attachments. The completed-document email attaches the full signed PDF, including its Certificate of Completion (which shows each Signer's name, email, IP address and device details). Negotiation emails can include an image of part of a document. Automation emails can include the signed PDF if the Customer chooses.
- Email tracking: Tally Sign doesn't use open or click tracking in its emails.
- Where: United States
- Transfer safeguard: Tally receives Customer Personal Data in the United States under the SCCs and UK Addendum in the DPA. Resend processes it in the United States under a written agreement that binds it to the same data protection obligations, as Clause 8.8 of the SCCs requires.
3.3 OpenRouter (AI request routing)
- Contracting entity: OpenRouter, Inc. (United States)
- What it does: Tally Sign's in-app AI assistant helps Users write, edit and review templates and drafts, and design automation emails. Tally sends each assistant request to OpenRouter, which passes it to a host that runs the AI model we have selected (Section 3.4) and returns the reply.
- When: Only when a User in the Customer's account uses the AI assistant. If nobody in the account uses it, no Customer Personal Data is sent to OpenRouter. A Customer can ask us to turn the assistant off for its account (DPA, Section 5.4), and we'll do so within 5 business days of the request.
- Customer Personal Data involved:
- For the template assistant: the draft or template being edited (its title, theme, page header and footer, and the text of every block, with images left out); the signers and people copied, with the names, email addresses, titles and companies entered for them; the fill-in values; the signing email's subject and message and the signing settings; the Customer's company name and legal name; what the Customer's own and other companies' public websites say about their names (see Section 4.3); the recent conversation with the assistant; and any pictures the User attaches. The assistant works only on drafts and templates, not on documents that have been sent. A draft can contain whatever the User has typed, such as client names and prices.
- For the email designer: the company name, brand color, whether the company has a logo, the current email design, subject and message text, the recent conversation, and any pictures the User attaches.
- Data use: OpenRouter and the model hosts use assistant content to return the reply. Under their terms, they don't use it to train AI models, and they may keep it for a limited time for abuse monitoring and to meet their legal obligations.
- What Tally keeps: Tally doesn't store the conversation with the assistant, and doesn't use it, or any other Customer Personal Data, to train AI models. We keep usage records (who used it, when, which model, how much, whether it succeeded and, if it failed, a short error message that can include the start of the reply) for 24 months. Pictures attached in the email designer are saved as email images so they can appear in the Customer's emails. Like other email images, anyone with their link can open them. Pictures the template assistant places in a draft are saved as part of that draft.
- Where: United States
- Transfer safeguard: Tally receives Customer Personal Data in the United States under the SCCs and UK Addendum in the DPA. OpenRouter processes it in the United States under a written agreement that binds it to the same data protection obligations, as Clause 8.8 of the SCCs requires.
- Terms and policies: OpenRouter Terms of Service and OpenRouter Privacy Policy.
3.4 AI model hosts (current models: Anthropic's Claude)
- What they do: Generate the AI assistant's replies. The assistant currently uses Anthropic's Claude models, reached through OpenRouter.
- Who runs the model: Anthropic's Claude models, served through OpenRouter by Anthropic or by cloud providers OpenRouter routes to (such as Amazon Bedrock or Google Vertex AI), in the USA. OpenRouter chooses which of these hosts handles each request. Tally has no direct contract with these hosts. OpenRouter must pass on to them the same data protection obligations (Section 1.3).
- Customer Personal Data involved: The same content described in Section 3.3, as passed on by OpenRouter.
- Where: United States
- Transfer safeguard: as for OpenRouter (Section 3.3).
- Usage policy: When you use the assistant, you must also follow Anthropic's Usage Policy, as our Acceptable Use Policy (Section 8.6) describes.
- Changing the model provider: We may move the assistant to a model from a different provider available through OpenRouter, or add a host. A new model provider or host is a new subprocessor. We will add it to this page and give notice under Section 5 before any Customer Personal Data is sent to it.
4. What isn't on this list, and why
4.1 Services the Customer or its Users choose to connect
The following services receive data only because the Customer or its Users connect them or tell Tally Sign to send data to them. They act under the Customer's or User's own agreement with that provider, not as Tally's subprocessors. The Customer is responsible for its use of them.
- ChatGPT, Claude and other Connected AI Apps. Any User can connect an AI app to Tally Sign (using the Model Context Protocol and a sign-in approval screen) to create and send documents from that app. What Tally Sign returns to the app goes to that app's provider under the User's own account and terms. That can include document and template content, Recipient names, email addresses, titles and companies, signing status and decline reasons, recent audit-trail events, data from the Customer's Salesforce org, links that let someone sign a pending document as the Recipient, and download links to completed PDFs, whose Certificate of Completion shows each Signer's IP address and device details. This is separate from the in-app AI assistant in Sections 3.3 and 3.4, even where the same company (for example Anthropic) is involved. An owner or admin can disconnect every connected app for the company at once in Settings.
- Salesforce. If the Customer installs the Tally Sign package and connects its own Salesforce org, Tally Sign reads record data from that org and writes envelope status, Recipient details, activity, record updates, tasks, notifications and the signed PDF back into it. Tally's reading and writing is processing under the DPA. Once data is in the Customer's org, Salesforce's processing of it is governed by the Customer's own agreement with Salesforce. Setup is described in the Salesforce guide.
- Sign-in providers and single sign-on. Users can sign in with Google, Microsoft or Salesforce, and a Customer can connect its own identity provider over SAML 2.0 or OpenID Connect (single sign-on). These are the User's or the Customer's own services, not Tally's subprocessors. When someone signs in this way, we receive their name, email address and a stable account ID from the provider (for Microsoft, also the tenant ID; for Salesforce, the org and user IDs). We never receive their password for that service.
- Slack, Microsoft Teams, Discord and webhooks. Automations can post messages to chat tools, or send document and Recipient details to a web address, that the Customer sets up.
- Email addresses the Customer enters. Automation emails go to any address the Customer chooses, sometimes with the signed PDF attached.
4.2 Our own billing provider
Stripe (Stripe, Inc., United States; stripe.com) handles checkout, subscriptions, invoices and the customer billing portal. Stripe receives the Customer's company name, billing email address and account identifier, and collects card details and billing address (and a tax ID, if the Customer adds one) directly. Card details never reach Tally's servers. This is data Tally handles for its own account and billing purposes, not Customer Personal Data processed on the Customer's behalf, so Stripe isn't listed as a subprocessor. How we and Stripe use billing data is described in our Privacy Policy.
4.3 Services that don't receive Customer Personal Data
- Fonts. Fonts are downloaded when we build the application and served from our own servers. Visitors' browsers don't contact a font provider.
- PDF creation and file conversion. Signed PDFs are generated, and uploaded PDF and Word files are converted, inside our own hosted application. No third-party service receives them.
- Company website lookups. When a User's message to the template assistant mentions a company's email address or website, our servers fetch the public home page of that company's website to read the company's name, and give what they find to the assistant. The request goes straight to that website and carries no Customer Personal Data beyond the website address itself. Free email providers (such as Gmail or Outlook) are never looked up.
- Analytics and advertising. Tally Sign and our website don't use analytics, advertising or tracking services. See our Cookie Notice.
5. How we tell you about changes
5.1 General authorization. By agreeing to the DPA, the Customer gives Tally general authorization to use the subprocessors on this page and to add or replace subprocessors by following this Section.
5.2 Notice before a change. At least 30 days before a new or replacement subprocessor starts processing Customer Personal Data, we will:
- (a) update this page, including the "Last updated" date and the change log in Section 8; and
- (b) email the Account Owner of each Customer account at the address on the account, and anyone who has asked for these notices under Section 5.3.
The notice will name the subprocessor and say what it will do, what Customer Personal Data it will process, and where.
5.3 Getting notices. Anyone at a Customer, such as a privacy or security lead, can ask to receive these notices by emailing privacy@tallysign.com with their name, company and the email address to use.
5.4 Objecting. A Customer may object to a new subprocessor on reasonable grounds relating to data protection by emailing privacy@tallysign.com within the notice period and explaining why. We will work with the Customer in good faith to address the concern, for example by suggesting a change in how the Customer uses the affected feature. For an AI model provider, the Customer may have the in-app AI assistant turned off for its account (DPA, Section 5.4), and if it does, we won't send its Customer Personal Data to the new provider.
5.5 If we can't resolve it. If we can't reasonably resolve the objection before the change takes effect, the Customer may end its subscription, or stop using the affected feature, by written notice to privacy@tallysign.com before the change takes effect. Termination takes effect on the date in the notice, even if that is before the end of the billing period. No further fees are charged after that date, and no early-termination fee applies. Termination under this Section is the Customer's only remedy for an objection to a subprocessor.
5.6 Urgent replacements. If we must replace a subprocessor urgently to keep the Service running or secure (for example, because a provider stops operating or suffers a security incident), we may do so with shorter notice. We will give notice as soon as we reasonably can, and the objection and termination rights in Sections 5.4 and 5.5 still apply.
5.7 Changes that need no advance notice. We will update this page without advance notice for changes that don't widen what a subprocessor does, such as a provider changing its name or its contact details, or a subprocessor being removed.
6. International transfers
6.1 Tally is based in the United States, and Tally Sign stores Customer Personal Data in the United States. Personal data from the European Economic Area, the United Kingdom or Switzerland is therefore transferred to the United States. The safeguards we use for those transfers, including the Standard Contractual Clauses and the UK Addendum where they apply, are set out in the Data Processing Addendum.
6.2 All of our subprocessors process Customer Personal Data in the United States, and each is bound by the same data protection obligations as Tally (Clause 8.8 of the SCCs). If that changes, Section 3 will say where and which additional safeguard applies, and we'll give notice under Section 5. On request, we will give Customers our transfer impact assessment (DPA, Section 10.8).
7. Contact
Questions about this list or our subprocessors: privacy@tallysign.com.
Postal address: available on request from support@tallysign.com.
We haven't appointed a representative in the European Union or the United Kingdom, or a data protection officer. Please send any privacy request or question to privacy@tallysign.com.
8. Change log
| Date | Change |
|---|---|
| September 27, 2026 | First published. |
